The DH group used in IKE phase 1 for initial SA. Valid options are DHGroup1, DHGroup14, DHGroup2, DHGroup2048, DHGroup24, ECP256, ECP384, or None.
DHGroup1
DHGroup14
DHGroup2
DHGroup2048
DHGroup24
ECP256
ECP384
None
The IKE encryption algorithm. Valid options are AES128, AES192, AES256, DES, or DES3.
AES128
AES192
AES256
DES
DES3
The IKE integrity algorithm. Valid options are MD5, SHA1, SHA256, or SHA384.
MD5
SHA1
SHA256
SHA384
The IPSec encryption algorithm. Valid options are AES128, AES192, AES256, DES, DES3, GCMAES128, GCMAES192, GCMAES256, or None.
GCMAES128
GCMAES192
GCMAES256
The IPSec integrity algorithm. Valid options are GCMAES128, GCMAES192, GCMAES256, MD5, SHA1, or SHA256.
The DH group used in IKE phase 2 for new child SA. Valid options are ECP256, ECP384, PFS1, PFS2, PFS2048, PFS24, or None.
PFS1
PFS2
PFS2048
PFS24
The IPSec SA payload size in KB. Must be at least 1024 KB.
1024
The IPSec SA lifetime in seconds. Must be at least 300 seconds.
300